Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

93 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.4%—NEC Aterm W300p Firmware9/1/201917/6/2026
Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.
ModificadaAlta (7.2)1.4%—NEC Aterm Wg1200hp Firmware9/1/201917/6/2026
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.
ModificadaAlta (7.2)1.4%—NEC Aterm Wg1200hp Firmware9/1/201917/6/2026
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.
ModificadaAlta (7.2)1.4%—NEC Aterm Wg1200hp Firmware9/1/201917/6/2026
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd in formWsc parameter.
ModificadaAlta (7.2)1.4%—NEC Aterm Wg1200hp Firmware9/1/201917/6/2026
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via formSysCmd parameter.
ModificadaAlta (7.5)2.3%—Aterm Wg2600hp2 Firmware24/8/201817/6/2026
An issue was discovered on the NEC Aterm WG2600HP2 1.0.2. The router has a set of web service APIs for access to and setup of the configuration. Some APIs don't require authentication. An attacker could exploit this vulnerability by sending a crafted HTTP request to retrieve DHCP clients, firmware version, and network…
ModificadaAlta (8.8)0.63%—Aterm Wf800hp Firmware1/4/201617/6/2026
Cross-site request forgery (CSRF) vulnerability on NEC Aterm WF800HP devices with firmware 1.0.17 and earlier allows remote attackers to hijack the authentication of arbitrary users.
ModificadaAlta (8.8)0.63%—Aterm Wg300hp Firmware1/4/201617/6/2026
Cross-site request forgery (CSRF) vulnerability on NEC Aterm WG300HP devices allows remote attackers to hijack the authentication of arbitrary users.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitDlink Dir-905l FirmwareDlink Dir-605l FirmwareDlink Dir-600l FirmwareDlink Dir-619l Firmware+221/5/201517/6/2026
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
ModificadaMedia (4.3)2.0%—Dmca Watermarker1/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in phprack.php in the DMCA WaterMarker plugin before 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the plugin_dir parameter.
ModificadaMedia (4.3)2.1%—Marekkis Watermark14/3/201416/6/2026
Cross-site scripting (XSS) vulnerability in the Marekkis Watermark plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pfad parameter to wp-admin/options-general.php. NOTE: some of these details are obtained from third party information.
ModificadaAlta (9.3)32%💥 ExploitVideocharge Watermark Master4/12/201317/6/2026
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the SourcePath value in a .wcf file.
ModificadaMedia (6.8)3.2%💥 ExploitVideocharge Watermark Master4/12/201317/6/2026
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the name attribute of the cols element in a .wstyle file.
ModificadaMedia (6.8)0.98%—NEC Atermwm3450rnNEC Atermwm3600rNEC Atermwr8160nNEC Atermwr8370n+219/3/201316/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the web-based management utility on the NEC AtermWR9500N, AtermWR8600N, AtermWR8370N, AtermWR8160N, AtermWM3600R, and AtermWM3450RN routers allow remote attackers to hijack the authentication of administrators for requests that (1) initialize settings or…
ModificadaBaja (3.7)0.36%—AtermEtermMrxvtMulti-aterm+37/4/200816/6/2026
rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a…
ModificadaAlta (7.5)2.3%💥 ExploitVM Watermark9/5/200716/6/2026
PHP remote file inclusion vulnerability in watermark.php in the vm (aka Jean-Francois Laflamme) watermark 0.4.1 mod for Gallery allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter.
ModificadaAlta (7.5)1.8%—Aterm18/3/200316/6/2026
The aterm terminal emulator 0.42 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
ModificadaAlta (7.5)1.8%—Aterm3/3/200316/6/2026
The menuBar feature in aterm 0.42 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.
Orbitaley — Vulnerabilidades